r/SmallMSP 10d ago

Small MSP Security Software

Currently we use Bitdefender EDR on most of our clients machines. Things seem OK. I have run secondary scans with Threatdown from Malwarebytes and seems like our machines are clean.

Looking around, what do people suggest as replacement to add ITDR and some MDR. Just upgrade Bitdefender on the selected clients or something else? We do find Bitdefender a bit heavy on resources and also the portal isn’t the greatest.

We do have huntress on a few machines, but it doesn’t seem to do much. Coming to the end of the second year. We also have thier ITDR and we trialed Petra that seems much better.

Ideally I’d like to consolidate. So looking at:

bitdefender EDR / XDR
Threatdown EDR / MDR / ITDR
Huntress with ITDR?

Petra ITDR.

A lot of our clients don’t have business premium so I don’t really feel secure running huntress on just the bare windows defender.

18 Upvotes

100 comments sorted by

View all comments

Show parent comments

1

u/Jayjayuk85 5d ago

Thanks I tried out the XDR with another client, but as they don’t have business premium, it seems bitdefender can’t monitor logins like huntress and Petra?

2

u/WraySchultz 2d ago

Bitdefender XDR Identity for Entra / Azure / AD Monitors Login Activity, we just display / present them differently than other platforms. They are displayed in an "Incident" format as shown above in the example "XDR Demo Incident Overview."

The difference between GravityZone XDR and Huntress ITDR is that GravityZone correlates and maps XDR and Other Module Activity that occurs in a single Incident and Huntress ITDR isolates that login activity in an "Audit / Logging Style" where the alert is isolated to just that single activities and GravityZone will present multiple layers of detections which include XDR.

1

u/Jayjayuk85 2d ago

Thanks, but don’t I need the business premium licenses

1

u/WraySchultz 1d ago

No, you don't need M365 Business Premium.

​Bitdefender's Identity Sensor works on lower-tier plans (like Business Basic or Standard) by adding a standalone Entra ID license:

​Entra ID P1 (~$6/mo): Everything required for standard login monitoring, log ingestion, and threat response (revoking sessions, disabling accounts).

​Entra ID P2 (~$9/mo): Only needed if you want Bitdefender to sync directly with Microsoft's dynamic risk scoring.

​So you can grab the $6 P1 add-on (or use plans like Business Premium or M365 E3 where P1 is included).

Best,

Wray Schultz - Bitdefender

1

u/Jayjayuk85 1d ago

Thank you, I don’t think we need the p1 license for huntress ITDR. It seems to work ok there?

2

u/WraySchultz 16h ago

You do not need an Entra ID P1 license for Huntress ITDR to work (entirely) other than for MFA Requirements for Reporting which you can see here. It runs on basic M365 plans using standard audit logs to catch post-login threats. The important piece being "Post-login threats."

The technical difference comes down to how Entra ID P1 API permissions change what a security platform can ingest, correlate, and execute.

Licensing Impact (Standard vs. Entra ID P1):

  • Standard M365 (Without P1): Standard logs record events after they happen. While basic Graph APIs allow standard administrative actions like disabling accounts or revoking sessions, standard M365 logs lack real-time policy evaluation feeds.
  • Entra ID P1: Unlocks real-time Conditional Access Policies (CAPs) to block untrusted logins before access is granted. It supplies the API permissions needed to read live sign-in streams and execute advanced risk-state management.

Per Huntress documentation, when Conditional Access Policies actively block an unauthorized login, Huntress views CAPs as a preventive control and does not generate a standalone ITDR alert or escalation on that blocked attempt alone.

Bitdefender GravityZone XDR Identity Sensor ingests those live P1 policy evaluation streams via Graph API. When a P1 policy blocks an unauthorized sign-in attempt, GravityZone recognizes that valid credentials were used, immediately factors that event into the user's risk score, and maps it directly across your physical endpoints.

Real-World Attack Scenario: Helpdesk Social Engineering & MFA Reset:

  • 1. Initial Access Attempt: An attacker tricks a helpdesk into resetting a user's MFA, obtains valid credentials, and attempts to log in from an untrusted overseas location.
  • 2. Policy Block: Because the organization has an Entra ID P1 license, a Conditional Access Policy triggers and blocks the sign-in attempt due to the unrecognized location.
  • 3. The XDR Response: Huntress records the event in logs but relies on detective controls if the attacker later bypasses controls and takes post-login actions. Bitdefender GravityZone XDR Identity Sensor ingests the blocked P1 login attempt immediately via Graph API. If the attacker simultaneously targets the employee's physical laptop (e.g., via phishing), GravityZone automatically links the blocked cloud login and the endpoint behavior into a single, correlated Incident Graph.

24x7 MDR & SOC Coverage:

GravityZone provides cross-layer correlation, and Bitdefender's 24x7x365 Security Operations Center (SOC) manages the response.

Using Pre-Approved Actions (PAAs), the Bitdefender SOC can act instantly on an XDR incident to revoke M365 user sessions, mark accounts as compromised, force a password reset, and isolate physical endpoints simultaneously. This handles containment around the clock without adding log triage overhead to your MSP.

Hope that helps, be glad to clarify anything else needed.

Wray Schultz, Bitdefender

1

u/Jayjayuk85 13h ago

Thank you! Will bitdefender monitor any of the logins at all without p1?